cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
This dumb password rule is from Replit.
Forces to use minimum 8 characters in the password and it must contain at least one uppercase.
https://dumbpasswordrules.com/sites/replit/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Michael T Babcock [https://en.pronouns.page/@bigntallmike] » 🌐
@mikebabcock@floss.social
Please use open source systems whenever possible so you can review the source code. Encourage vendors you work with to stop keeping their software hidden so it can be audited.
Slovakia discovers Russian backdoors in 279 new traffic cameras — SMS-triggered shell access and passwordless live feeds found in EU-funded rollout | Tom's Hardware
https://www.tomshardware.com/tech-industry/cyber-security/slovakia-discovers-russian-backdoors-in-279-new-traffic-cameras-national-security-service-deactivates-offending-units
For those who can read the original:
https://www.sk-cert.sk/sk/varovanie-pred-rizikami-cestnych-meradiel/index.html
This dumb password rule is from SONY.
- between 8 and 30 characters
- at least one number or special character
- not part of email address
- avoid common passwords
- repeating characters 3 or more times should be avoided
- currency characters and 3 or more consecutive characters, also in reverse order, should be avoided
Somehow "$" i...
https://dumbpasswordrules.com/sites/sony/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Mobility.
The username is the customer number, which is sequential and cannot be changed, currently 7 digits long for new customers.
The password has to be exactly 6 digits long, only numbers allowed.
https://dumbpasswordrules.com/sites/mobility/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
#Bluesky says its recent outage was caused by another #DDoS attack
https://techcrunch.com/2026/08/18/bluesky-says-its-recent-outage-was-caused-by-another-ddos-attack/
This dumb password rule is from Dnevnik.ru.
Silently (sic!) trim password to 30 symbols.
That causes the stupid case when you could successfully registrate an account with password length of 52 and can't login with the password.
https://dumbpasswordrules.com/sites/dnevnik-ru/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from CWT Business Travel Management Company.
Password:
- 8 to 32 characters long
- Must contain a combination of letters, numbers and symbols
- Must be different from your username
- Must be different from 5 previous passwords
https://dumbpasswordrules.com/sites/cwt-business-travel-management-company/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Jaa Lifestyle.
When we try to change password and accidentally gave a wrong password for confirm password.
Lets try to read and figure out what they are trying to point out.
https://dumbpasswordrules.com/sites/jaa-lifestyle/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Ticketmaster.de.
Your password length is limited between 8 and 32 characters.
https://dumbpasswordrules.com/sites/ticketmaster-de/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Nectar API.
The Nectar website allows strong passwords.
However, when trying to link my Sainsbury's account, I found the API has different ideas...
- Password field length capped to 16 characters
https://dumbpasswordrules.com/sites/nectar-api/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Researchers found a new way to get the original prompt back just by looking at the AI text output. It works with very high accuracy. This is a real risk for private user data and secret system prompts.
This dumb password rule is from Kryterion Webassessor.
I was quite surprised to see this when I was registering for my Google Professional Cloud **Security** Engineer certification. Nice part is that they **don't allow quotes** as special character, so I assume there possibly might be some other issues on their backends. :-)
https://dumbpasswordrules.com/sites/kryterion-webassessor/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Wow! "'Near-autonomous' AI agents attack Taiwan's nuclear safety agency"
"Over... four days of July, AI agents compromised 85 government user accounts and extracted more than 2,500 personnel records, according to Dream, an Israeli cybersecurity firm."
https://www.theregister.com/security/2026/08/12/near-autonomous-ai-agents-attack-taiwans-nuclear-safety-agency/5287055
h/t @patrickcmiller
https://infosec.exchange/@patrickcmiller/117110192247221786
Dream Group: "Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia"
https://www.dreamgroup.com/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asia
#AI #cybersecurity #China #Taiwan #geopolitics #hacking
This dumb password rule is from USAA Bank.
Password cannot be longer than 12 characters but they don't tell you that until after you try a new password. To make up for this fact they've added dubious additional security features on top of this weak foundation.
https://dumbpasswordrules.com/sites/usaa-bank/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
NIST is asking the #cybersecurity industry how AI should reshape the NVD after cutting routine CVE enrichment.
As of today, "Not Scheduled CVEs" outnumber active enrichment by nearly 14 to 1.
Here's the latest →
https://socket.dev/blog/nist-nvd-ai-automation
This dumb password rule is from Credit Union Australia (CUA) Health.
Password must be between 7 and 10 characters, contain both an uppercase and a lowercase letter and have at least one number.
https://dumbpasswordrules.com/sites/credit-union-australia-cua-health/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Australia Immi Platform.
The Australian immigration platform requires at least 14 characters and at least one from three of the four groups: lowercase letters, uppercase letters, digits, and special characters.
The random generator in my password manager only needed one second attempt to avoid 'dangerous' special charact...
https://dumbpasswordrules.com/sites/australia-immi-platform/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from SecureAccess Washington.
Central authentication for all Washington State services
(DoL, ESD, etc).
Password must have *exactly* 10 characters, but form happily
lets you enter more and only throws errors after submit,
providing no useful feedback.
https://dumbpasswordrules.com/sites/secureaccess-washington/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Copart.
Copart: "The security of our members is extremely important to us."
Also Copart: "We're gonna need you to keep your password between 5-10 characters."
https://dumbpasswordrules.com/sites/copart/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from O2 Spain.
When registering in *Mi O2* app, password length must be exactly 7 or 8 characters (numbers and letters only).
As O2 is part of Telefónica (Movistar), it seems to use the same backend (at least in Spain), so it has the [`same password requirements`](https://dumbpasswordrules.com/sites/movistar/).
https://dumbpasswordrules.com/sites/o2-spain/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Gigabyte RMA system.
Your password must contain:
Between 8-12 characters
An upper case letter (A, B, C, etc.)
a lower case letter (a, b, c, etc.)
A number (1, 2, 3, etc.)
A symbol (-, ~, !, #, $, %, &, (, ), +, =, .)
https://dumbpasswordrules.com/sites/gigabyte-rma-system/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from NVV (Nordhessische VerkehrsVerbund).
Password length must be 4 to 10 characters with only a few special characters allowed.
https://dumbpasswordrules.com/sites/nvv-nordhessische-verkehrsverbund/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
@briankrebs Anything on the new exe order #Trump Authorizes Private Firms for #Cybersecurity
Operations Against Foreign Criminals🕵🏼♀️
Hey gang, we need to talk about the recent presidential memorandum authorizing offensive security operations by the private sector. That's because I care about your safety, the rule of law, and a functioning internet. A lot of folks might be excited about the opportunity to use their hacking skills to take out bad actors and criminals in a way that's safe and legal for them. That's not what this is.
At best, this memo provides you with some limited protection from prosecution by the federal government for what's otherwise criminal activity. That protection is only provided if you follow their rules. And it's only as good as Trump's promises, only as long as he perceives you to be useful to him personally, and possibly only as long as Trump retains power.
It provides you with no protection against prosecution by other jurisdictions. You are not a government actor or a uniformed soldier, so you will have no protections from prosecution under sovereign immunity or as a lawful combatant.
Every one of these actions is likely to be considered a criminal offense in every jurisdiction that your operations impact. That includes direct operations as well as support (e.g., offsec tool building, standing up infrastructure for malware delivery or C2). It includes the jurisdictions that your targets are in, as well as every jurisdiction that your operations travel through and that host your infrastructure. It includes upstream and downstream actions by other operators that you might not be fully aware of, if they can tie you to a criminal conspiracy.
Your identity and your operations will not remain secret. This administration has shown they cannot and will not keep secrets. Our president was charged with criminal violations of the espionage act, and his drunkard of a SECDEF has notoriously leaked classified details of military operations to a reporter, so we know they're not trustworthy with secrets.
We've shown that governments can identify and charge cyberespionage operators since the APT1 indictments in 2014, and in some cases we've even successfully arrested, tried, and imprisoned hackers operating for foreign governments. You should assume that other countries have similar investigative capabilities.
You will be subject to arrest, extradition, trial, and imprisonment every time you set foot abroad for business, vacation, or visiting family, possibly for the rest of your life. You could be subject to international sanctions that might freeze your finances. You'll almost certainly wind up a target for intelligence collection by foreign intelligence services. You could also be considered an unlawful combatant and legitimate target for kinetic and non-kinetic military operations by the military forces of the countries you've pissed off.
You should also consider the unreliability of the Trump regime's designations for targeting. They've routinely designated civilian or even functionally nonexistent organizations as criminal or terrorist organizations. You cannot trust their assurances that the bad guys you're harming are actually bad guys.
Please don't make a dumb decision that ruins your life, especially not for the false promises of the Trump regime.
This dumb password rule is from Afraid.org FreeDNS.
Password must be between 4 and 16 characters long
https://dumbpasswordrules.com/sites/afraid-org-freedns/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Michigan.gov.
Must use special characters, but only from this list of stuff we think is safe or whatever.
https://dumbpasswordrules.com/sites/michigan-gov/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Smart Glasses Are Catching on With U.S. Police
At least two sheriff's offices in Florida have purchased Ray-Ban Meta AI glasses.
https://gizmodo.com/smart-glasses-are-catching-on-with-u-s-police-2000797054
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #Gizmodo [Gizmodo]
This dumb password rule is from amaysim.
Passwords must be 6-15 characters. If you enter more than 15 characters at signup, there is no error,
but the system apparently silently truncates to 15 characters. So of course, logging in subsequently
fails if you enter the untruncated password. How convenient.
https://dumbpasswordrules.com/sites/amaysim/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Benergy4.
12 to 25 characters, only these special chars allowed: @+/'!#$^?:,.(){}[]~-.
Also, security questions.
https://dumbpasswordrules.com/sites/benergy4/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Targobank.
Your password must:
- must not be your username
- must at least eight characters
- must contain at least one number character
- must contain at least one uppercase character and 1 lowercase character
- must not contain spaces
- must not contain three identical characters in a row
- must not conta...
https://dumbpasswordrules.com/sites/targobank/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from El Corte Ingles.
Min 6 and max 8 characters for password! Can't contain anything
different than letters and numbers. Apart, the email address must have
at least 8 characters (sorry million dollar domain owners! :D)
https://dumbpasswordrules.com/sites/el-corte-ingles/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
boostedWer seinen eigenen Mailserver betreibt, kennt das Problem
Ich betreibe neben vielen privaten Domains auch meinen eigenen Mailserver, da hängt viel an einer sauber konfigurierten Domain: DNS-Einträge exakt, TLS sauber, SSH gehärtet. Wer das prüfen will, trifft auf ein Dutzend Scanner, die fast alle dasselbe tun: sich einen einzigen Ausschnitt anschauen und ab einem gewissen Punkt ein Konto oder eine Kreditkarte verlangen. Deshalb gibt es jetzt Secure Your Server: acht Kategorien von DNS bis PGP in einem einzigen Scan, dazu ein echter Mail-Zustellungstest, für immer kostenlos, ohne Konto, ohne Tracking. Teste deine eigene Domain, bevor es jemand mit weniger guten Absichten tut.
#chrislo #digitaleunabhängigkeit #itsicherheit #cybersecurity #infosec #opensource #selfhosting #datenschutz #dsgvo #digitalesouveränität #security #vereine
This dumb password rule is from Bendigo Bank.
**Exactly** eight characters.
https://dumbpasswordrules.com/sites/bendigo-bank/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Netflix.
[The help page](https://help.netflix.com/de/node/54078)
and the [password reset page](https://www.netflix.com/password) say:
Ihr Passwort muss zwischen 4 und 60 Zeichen lang sein und darf keine Tilde (~) enthalten.
https://dumbpasswordrules.com/sites/netflix/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
“Hacker summer camp is over, everyone go home! Black Hat, Def Con, and BSides Las Vegas sounded like they were all pretty great this year... if you were there. I was not, and so I missed out on some incredible talks — but escaped the awful Las Vegas heat. Not all bad, then.
Instead, I was living vicariously through the week of live streams, the incredible reporting from the show, and what people on the ground were telling me. (Thank you for all the tips, and keep them coming by email or via Signal at zackwhittaker.1337.)
Pour yourself some coffee (or alternative) and catch up with some of my choice highlights from the week.”
This dumb password rule is from BinckBank.
Between 10 and 16 letters and/or digits. No special characters are allowed.
Must be renewed at least every 180 days, but you can configure to let the password expire sooner.
When changing the password, the new password cannot be too similar to the existing password.
https://dumbpasswordrules.com/sites/binckbank/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Techcombank.
Your password must:
- Be between 6 and 8 characters long
- Contains at least 1 number character
- Contains at least 1 lowercase character
- Contains at least 1 uppercase character
- Neither space nor unicode character is allowed. In fact,
NO special characters is allowed
- Must be changed every 9...
https://dumbpasswordrules.com/sites/techcombank/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from PayPal.
Must be between 8 and 20 characters, no spaces, uppercase and lowercase, one symbol...
The rule limits special characters to !@#$%^&*(). but my current password has a "-" in it so someone decided to restrict this further which is totally backwards. Things are meant to get better not worse!
https://dumbpasswordrules.com/sites/paypal/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from AOK (German Health Insurance).
This is the online customer portal of the German health insurance company AOK. They have an extensive set of rules for both passwords and usernames.
The password rules are:
- Length between 8 and 14 characters
- At least one letter, one number and one special character
- Special characters are: !...
https://dumbpasswordrules.com/sites/aok-german-health-insurance/
#password #passwords #infosec #cybersecurity #dumbpasswordrules